ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ20ÖÜ

Ðû²¼Ê±¼ä 2019-05-20

±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö



2019Äê5ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼Çå¾²Îó²î74¸ö£¬£¬ £¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Remote Desktop Services CVE-2019-0708Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£» £»£»£»Adobe Media Encoder CVE-2019-7842ÊͷźóʹÓÃÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£» £»£»£» Facebook WhatsApp CVE-2019-3568»º³åÇøÒç³öÎó²î£»£» £»£»£»Apple Safari¶à¸öÄÚ´æÆÆËðí§Òâ´úÂëÖ´ÐÐÎó²î£»£» £»£»£»Adobe AcrobatºÍReader¶à¸öÊͷźóʹÓôúÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ΢ÈíÐÞ¸´79¸öÎó²î£¬£¬ £¬£¬£¬£¬£¬°üÀ¨RDPÖеÄRCEÎó²î£¨CVE-2019-0708£©£»£» £»£»£»¹¥»÷ÕßʹÓûªË¶ÖÐÐÄÈ˹¥»÷·Ö·¢PleadºóÃÅ£»£» £»£»£»Stack OverflowÐû²¼Í¨¸æ³ÆÆäÔâºÚ¿ÍÈëÇÖ£»£» £»£»£»Î´ÉèÃÜÂëµÄÊý¾Ý¿âй¶½ü90%°ÍÄÃÂí¹«ÃñÐÅÏ¢£»£» £»£»£»¶íÂÞ˹ºÚ¿Í×éÖ¯³öÊÛÃÀ¹ú3´ó·´²¡¶¾¹«Ë¾Ô´Âë¡£¡£¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬ £¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£



Ö÷ÒªÇå¾²Îó²îÁбí



1. Microsoft Windows Remote Desktop Services CVE-2019-0708Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft Windows Remote Desktop Services´¦Öóͷ£Äڴ湤¾ß±£´æÄÚ´æÆÆËðÎó²î£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄRDPÇëÇ󣬣¬ £¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣» £»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708

2. Adobe Media Encoder CVE-2019-7842ÊͷźóʹÓÃÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Adobe Media Encoder´¦Öóͷ£Îļþ±£´æÄÚ´æÆÆËðÎó²î£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬ £¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣» £»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/media-encoder/apsb19-29.html

3. Facebook WhatsApp CVE-2019-3568»º³åÇøÒç³öÎó²î
Facebook WhatsApp±£´æ»º³åÇøÒç³öÎó²î£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://www.facebook.com/security/advisories/cve-2019-3568

4. Apple Safari¶à¸öÄÚ´æÆÆËðí§Òâ´úÂëÖ´ÐÐÎó²î
Apple Safari WebKit±£´æ¶à¸öÄÚ´æÆÆËðÎó²î£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³ÇëÇ󣬣¬ £¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://support.apple.com/zh-cn/HT210123

5. Adobe AcrobatºÍReader¶à¸öÊͷźóʹÓôúÂëÖ´ÐÐÎó²î
Adobe AcrobatºÍReader±£´æÊͷźóʹÓÃÎó²î£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³ÇëÇ󣬣¬ £¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬ £¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣» £»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/acrobat/apsb19-18.html


Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö



1¡¢Î¢ÈíÐÞ¸´79¸öÎó²î£¬£¬ £¬£¬£¬£¬£¬°üÀ¨RDPÖеÄRCEÎó²î£¨CVE-2019-0708£©

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Öܶþ΢ÈíÐû²¼5ÔÂWindowsÇå¾²¸üУ¬£¬ £¬£¬£¬£¬£¬ÐÞ¸´79¸öÎó²î¡£¡£¡£¡£¡£¡£¡£ÆäÖаüÀ¨RDPЧÀÍÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0708£©£¬£¬ £¬£¬£¬£¬£¬´ËÎó²îÊÇÔ¤Éí·ÝÑéÖ¤£¬£¬ £¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥£¬£¬ £¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ룻£» £»£»£»ÌáȨ0day£¨CVE-2019-0863£©£¬£¬ £¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¹¥»÷ÕßÌáÉýÖÁÖÎÀíԱȨÏÞ£»£» £»£»£»Õë¶ÔIntel CPU MDS¹¥»÷µÄÎó²îÐÞ¸´£¬£¬ £¬£¬£¬£¬£¬ÕâЩÎó²îÓ°ÏìÁË2011ÄêÒÔÀ´ÏÕЩËùÓеÄIntel CPU¡£¡£¡£¡£¡£¡£¡£ÍêÕûÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-may-2019-patch-tuesday-arrives-with-fix-for-windows-zero-day-mds-attacks/

2¡¢¹¥»÷ÕßʹÓûªË¶ÖÐÐÄÈ˹¥»÷·Ö·¢PleadºóÃÅ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


4ÔÂβESETÑо¿Ö°Ô±ÊӲ쵽ʹÓá°AsusWSPanel.exe¡±·Ö·¢PleadºóÃŵĹ¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£AsusWSPanel.exeÊÇ»ªË¶Ôƴ洢ЧÀÍWebStorageµÄWindows¿Í»§¶Ë¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±¸ø³öÁËÁ½ÖÖ¿ÉÄܵĹ¥»÷³¡¾°£¬£¬ £¬£¬£¬£¬£¬Ò»ÖÖÊÇ»ªË¶Ôâµ½¹©Ó¦Á´¹¥»÷£¬£¬ £¬£¬£¬£¬£¬ÁíÒ»ÖÖÊǹ¥»÷ÕßʹÓÃÖÐÐÄÈ˹¥»÷ºÍÒ×Êܹ¥»÷µÄ·ÓÉÆ÷À´Èö²¥¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£½øÒ»²½µÄÆÊÎöºóÑо¿Ö°Ô±ÒÔΪºóÒ»ÖÖ¹¥»÷³¡¾°µÄ¿ÉÄÜÐÔ¸ü´ó¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/bad-actors-using-mitm-attacks-against-asus-to-distribute-plead-backdoor/

3¡¢Stack OverflowÐû²¼Í¨¸æ³ÆÆäÔâºÚ¿ÍÈëÇÖ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


5ÔÂ16ÈÕStack OverflowÐû²¼ÁËÒ»Ìõ¼ò¶ÌµÄͨ¸æ£¬£¬ £¬£¬£¬£¬£¬³Æ5ÔÂ11ÈÕºÚ¿ÍÈëÇÖÁËÆäÉú²úϵͳ¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Stack Overflow¹¤³Ì¸±×ܲÃMary FergusonµÄ˵·¨£¬£¬ £¬£¬£¬£¬£¬ºÚ¿Í»ñµÃÁËÒ»¶¨Ë®Æ½µÄÉú²úϵͳ»á¼ûȨÏÞ£¬£¬ £¬£¬£¬£¬£¬Stack Overflow·¢Ã÷²¢ÊÓ²ìÁË»á¼ûµÄ¹æÄ££¬£¬ £¬£¬£¬£¬£¬²¢ÇÒÐÞ¸´ÁËËùÓеÄÒÑÖªÎó²î¡£¡£¡£¡£¡£¡£¡£ÊÓ²ìûÓз¢Ã÷ºÚ¿Í»ñµÃÓû§Êý¾ÝµÄÈκÎÖ¤¾Ý¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚÊÓ²ìÕýÔÚ¾ÙÐÐÖУ¬£¬ £¬£¬£¬£¬£¬Òò´ËStack Overflow²¢Î´Åû¶¸ü¶àϸ½Ú¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/stack-overflow-says-hackers-breached-production-systems/

4¡¢Î´ÉèÃÜÂëµÄÊý¾Ý¿âй¶½ü90%°ÍÄÃÂí¹«ÃñÐÅÏ¢


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²Ñо¿Ô±Bob DiachenkoʹÓÃShodanÔÚAWSÉÏ·¢Ã÷Ò»¸öδÊܱ£»£» £»£»£»¤µÄElasticsearchÊý¾Ý¿â£¬£¬ £¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âй¶ÁËÊý°ÙÍò°ÍÄÃÂí¹«ÃñµÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄ±íÊö£¬£¬ £¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨3427396Ìõ±êǩΪ¡°»¼Õß¡±µÄ¼Í¼ÒÔ¼°468086Ìõ±êǩΪ¡°²âÊÔ»¼Õß¡±µÄ¼Í¼¡£¡£¡£¡£¡£¡£¡£ÕâЩÐÅÏ¢°üÀ¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éí·ÝÖ¤ºÅÂë¡¢µØµã¡¢ÓÊÏäºÍµç»°ºÅÂëµÈ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÊý¾ÝûÓÐÖØ¸´£¬£¬ £¬£¬£¬£¬£¬ÕâЩ¼Í¼Լռ¸Ã¹ú×ÜÉú³ÝµÄ90%¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/sensitive-information-of-millions-of-panama-citizens-leaked/

5¡¢¶íÂÞ˹ºÚ¿Í×éÖ¯³öÊÛÃÀ¹ú3´ó·´²¡¶¾¹«Ë¾Ô´Âë


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


×Ô3Ô·ÝÒÔÀ´£¬£¬ £¬£¬£¬£¬£¬¶íÂÞ˹ºÚ¿ÍÍÅ»ïFxmspÔÚµØÏÂÂÛ̳ÉÏÐû³Æ³öÊÛÈý¼ÒÃÀ¹ú·´²¡¶¾¹«Ë¾µÄÈí¼þ²úÆ·Ô´ÂëºÍ¹«Ë¾ÍøÂç»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£ÆðÔ´µÄ¼ÛÇ®ÊÇ»á¼ûȨÏÞ25ÍòÃÀÔª£¬£¬ £¬£¬£¬£¬£¬Ô´´úÂë15ÍòÃÀÔª£¬£¬ £¬£¬£¬£¬£¬µ«±¨¼Û²¢²»Àο¿¡£¡£¡£¡£¡£¡£¡£Fxmsp²¢Î´Ö¸³öÏêϸµÄ¹«Ë¾Ãû³Æ£¬£¬ £¬£¬£¬£¬£¬µ«ÌṩÁ˰üÀ¨30TBÊý¾ÝµÄÎļþ¼Ð½ØÆÁ£¬£¬ £¬£¬£¬£¬£¬¾Ý³ÆÕâЩÊý¾Ý°üÀ¨¿ª·¢Îĵµ¡¢È˹¤ÖÇÄÜÄ£×Ó¡¢WebÇå¾²Èí¼þºÍ·´²¡¶¾Èí¼þµÄ´úÂëµÈ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-selling-access-and-source-code-from-antivirus-companies/